Record summary

CVE-2018-6835 has a selected CVSS score of 9.8 (critical).

Description

node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.

Description source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 1.6.3 · Fixed in 1.6.3affected

References

4